WASHINGTON—The acting director of the Cybersecurity and Infrastructure Security Agency (CISA) testified to Congress on May 8 about efforts to counter cyberattacks by the Chinese Communist Party (CCP) in the United States.
The cybersecurity agency, she said, is helping companies with mitigation strategies against Chinese cyber threats.
“The more we can make it hard for them to get into our critical infrastructure, the better it is,” Bean said, in response to a question from Rep. Dan Newhouse (R-Wash.) about the adequacy of U.S. infrastructure to defend against the Chinese regime.
Bean said that the core capability of CISA was its “attack surface management program,” whereby the agency detects common types of hacking and then advises private companies on how to issue “software patches” that will protect against them.
“The attack search management, not only is it one of our most scalable [and] cost-effective tools we have, [but also] it’s the most effective [in] identifying vulnerabilities and providing an entity to fix that, to mitigate that challenge,” Bean remarked in response to a question from Rep. Ashley Hinson (R-Iowa).
Bean also described how the agency was advocating against the use of TikTok, a social media platform owned by the Chinese company ByteDance that is subject to Chinese national security laws, which require companies to furnish any personal data they possess to Beijing.
“China is the most prolific, dominant threat we have, and they are [hacking us] for three reasons. They are doing it for espionage, they’re doing [it] to steal our intellectual property, and they are getting into our critical infrastructure,” Bean said.
“They are waiting to disrupt or destroy our critical infrastructure at the time and place of their choosing, and they want ... to discourage us should there be a conflict with China over Taiwan.”